# Set up roles and permissions

<Lead>
Not everyone in the office needs access to everything. Under **Settings > Roles** you define what a role may see and do. Individual exceptions for one person are handled in their profile.
</Lead>

## Two paths, and when to take which

| You want … | Go to |
|---|---|
| several people to have the same access | **Settings > Roles** |
| exactly one person to have more or less | **Settings > Members > Person > Permissions** |

When in doubt, use the role. Setting forty switches per person gets unmanageable fast, and usually ends with everyone getting the same access anyway.

---

## The four standard roles

| Role | In short |
|---|---|
| Owner | Full access, including billing and deleting the workspace. |
| Admin | Manage settings, team and tools. Cannot delete the workspace. |
| Member | Edit properties and appointments, use tools. No billing or team management. |
| Viewer | See everything, change nothing. |

These four exist in every workspace. You can view them but not change them. If you need a variation, build a custom role on top of one.

**Click a role to see what it may do.** This works for the standard roles too. The page shows every permission in the same layout as a custom role, only locked, and below it who currently holds the role.

---

## Who may change which role?

Since 5 September 2026 two rules apply, and both come down to the same sentence: **nobody grants more than they hold themselves.**

<DefinitionList>
  <DefItem term="Only roles below your own">An admin manages **Member**, **Viewer** and custom roles built on those. The **Admin** role itself is the owner's to change, and so is any custom role inheriting from Admin. Otherwise every admin could grant themselves the permissions they lack, and two levels would collapse into one.</DefItem>
  <DefItem term="Only permissions you hold">A permission you do not have yourself cannot be given to anyone. Those rows are marked **gesperrt** (locked) in the permission matrix instead of moving and then being rejected on save. Taking a permission away stays possible.</DefItem>
  <DefItem term="Not your own permissions">Neither your own role nor your own personal exceptions are yours to change, and you do not remove a member on your own level. If you are missing a permission for your work, the owner grants it.</DefItem>
</DefinitionList>

Permissions already granted are untouched: the rule works forward and takes nothing away. A role the owner once gave a special permission can still be edited in every other respect.

<Callout tone="info">
None of these limits apply to the owner. They hold every permission and can edit every role.
</Callout>

---

## Ready-made roles: the fastest route

At the bottom of **Settings > Roles** you will find ready-made roles cut for everyday estate-agency work. One click on **Create this role** turns one into an ordinary custom role that you can change freely afterwards.

| Ready-made role | For whom | What it can do |
|---|---|---|
| Apprentice | Trainees still learning the ropes | Works on their own properties. No credential vault, no website, no WhatsApp bot. |
| Back office | Internal staff | Keeps properties, files and appointments in order, may share files externally, never appears outward themselves. |
| Agent, own portfolio | Field staff with their own patch | Sees only their own properties and contacts, otherwise everything a member can do. |
| Team lead | Leadership without the commercial side | Invite the team and assign roles, but no billing, no domain, no keys. |
| Accounting | Tax adviser, commercial staff | Sees billing and activity, changes nothing in the portfolio. |
| External service | Photography, image editing | Delivers material for assigned properties. Homestaging and image-to-video yes, deleting no. |

Once created, a role disappears from this list. From then on it is an ordinary custom role: rename it, change its permissions, delete it, all possible.

---

## Creating a custom role by hand

For when none of the ready-made roles fits. Typical case: temporary staff should work like a normal member, but not touch the website.

1. Go to **Settings > Roles**.
2. Click **Create blank role**.
3. Enter a name, for example "Temp".
4. Under **Inherits from**, choose the standard role that serves as the base. Here: *Member*.
5. Click **Create**. You land directly on the new role's page.
6. Turn off what it should not be able to do. For the website: the main switch **Open website**.
7. Click **Save**.

From now on you can assign this role like any standard role. Change the role later and it applies immediately to everyone who has it.

<Callout tone="info">
A custom role always inherits from exactly one standard role and differs only where you say so. Anything you leave alone keeps following the standard role.
</Callout>

**If you change the base later**, the system cleans up: deviations that are no longer deviations under the new base disappear. For example, "website off" is a deviation from *Member* but not from *Viewer*, where the website is off anyway.

---

## Assigning a role

Custom roles appear everywhere the standard roles do:

| Where | When |
|---|---|
| **Settings > Members**, dropdown in the row | quick change |
| **Settings > Members > Person**, section *Role & access* | while reviewing a person |
| **Settings > Members > Create account** | right at creation, as its own card next to the standard roles |
| Setting up a vacant seat | when a seat is reassigned after offboarding |

---

## The main switch per tool

Every tool has one permission marked **main switch**. It decides whether the tool exists for that person at all.

With the main switch off, the tool is **gone**: not on the home screen, not under *Tools*, and a direct link leads to a short notice instead of the interface. It is not shown greyed out. Someone who is not allowed to use something should not have to keep reading that it exists.

The finer permissions of a tool (for example "Publish" for the website) only take effect while the main switch is on.

---

## An exception for one person

Example: all members may edit page content, but only Anna may actually publish the website.

1. Go to **Settings > Members** and open the person.
2. Click **Permissions for this person**.
3. Flip the switch you want. It gets marked as **differing**.
4. Click **Save** at the bottom.

Only the differences are stored. Everything else keeps following the role. Change the role later and it reaches this person too, except for the exact switches you set differently here.

Use **differing · reset** to remove an exception. From then on the person follows their role again on that point.

<Callout tone="warning">
The owner role always has full access. Exceptions cannot be set for it. If you want to limit yourself, transfer ownership first.
</Callout>

---

## Spotting far-reaching permissions

Permissions with a warning icon act outward or cannot be undone. For example:

- **Publish** (website): the page goes live for every visitor.
- **Delete permanently** (files): the trash is emptied, the file is gone.
- **Share externally** (files): creates a link that outsiders can open.
- **Start database scan** (DB leads): consumes AI budget.

Grant these deliberately, and to as few people as possible.

---

## Exports: every route out has its own permission

An **export** is any function that hands data out of the workspace as a file: a CSV, a ZIP, a list to take along. Once something sits on a private machine you cannot pull it back and you cannot delete it, and when a subject access request arrives you can no longer say where it ended up.

That is why the same rule applies to every export:

<Callout tone="warning">
**Exports are separate permissions and are off by default for members.** They never hang off a tool's main switch and never off the read permission. Being allowed to look at a list does not mean being allowed to take it away.
</Callout>

### The nine exports

| Permission | What leaves | Where |
|---|---|---|
| Export own account data | Your own account data as a file. | My account, privacy |
| Export activity log | The workspace log, including the names and email addresses of the people who acted. | Settings, activity |
| Export marketing objections | The suppression list with name, email and objection per channel. | Settings, communication |
| Export processing records | The Article 30 record, including the gaps it declares. | Settings, privacy |
| Export contacts | The filtered database with names, contact details and scoring. | DB leads |
| Download appointments as a file | The appointment list with guests' names, email addresses and phone numbers. | Appointment booking |
| Download folder as an archive | A selection or a whole folder as a ZIP. | Files |
| Download batch as an archive | Every finished image of a batch as a ZIP. | Image optimiser |
| Export entries | Credentials from the vault. | Credential vault |

Viewing and downloading a single file is untouched by this. What is meant is reaching for the whole folder, not opening one brochure.

### What happens when you turn one on

Flip an export on for a role or a person and the system asks first. That is neither a formality nor a click to dismiss: turning it on transfers responsibility for the exported data to you. It is written down in the [terms of use, section 12 (4)](/legal/terms).

In practice: from the moment a file leaves the workspace our control over it ends. What happens to it afterwards is yours to answer for as the controller.

<Callout tone="info">
The confirmation appears for every permission whose name ends in `.export`. That is deliberate: were it driven by a maintained list instead, the next new export route would be the one without a confirmation.
</Callout>

### How to grant one

1. Go to **Settings > Roles** and open the role, or to **Settings > Members > person > permissions**.
2. Search at the top for "export" or "download".
3. Flip the switch and confirm the prompt.
4. Click **Save** at the bottom.

Take the person, not the role, when exactly one person needs the export. An export on the "Member" role grants it to everyone, including the people you add next week.

<Callout tone="warning">
Review a granted export regularly. Someone who got it for a one-off package for the tax adviser does not need it afterwards, and a permission nobody thinks about any more is a permission nobody takes away either.
</Callout>

---

## Deleting a role

When you delete a custom role, the system tells you how many people are affected and moves them to the standard role the deleted role inherited from. Nobody loses access unnoticed.

---

## Common questions

**I cannot see the Roles area.**
Only owners and admins may manage roles. Check your own role under *Settings > Members*.

**Someone reports that a tool has disappeared.**
Check the tool's main switch, first in that person's role, then in their personal exceptions. A main switch that is off hides the tool everywhere.

**Do changes take effect immediately?**
Yes, on the affected person's next page load. No new sign-in required.

**Can a custom role inherit from another custom role?**
No, only from one of the four standard roles. That keeps it traceable where a permission comes from.

**Can I hand out the Owner role?**
No, it appears in no role dropdown. You transfer ownership in the profile of the person taking it over, so it cannot be passed on by accident.

**I created a ready-made role and it does not quite fit.**
Open it and change what you need. A ready-made role is only a starting point; after that it is yours.

**When creating an account it says the role no longer exists.**
It has been deleted or renamed in the meantime. Reload the page and the current choices appear.
